CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-97641
7.2 HIGH

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, …

Oct 2, 2026
CVE-2026-97342
7.2 HIGH

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in …

Oct 2, 2026
CVE-2026-97336
7.2 HIGH

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to …

Oct 2, 2026
CVE-2026-96871
7.2 HIGH

The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due …

Oct 2, 2026
CVE-2026-96578
7.2 HIGH

The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up …

Oct 2, 2026
CVE-2026-96567
7.2 HIGH

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 …

Oct 2, 2026
CVE-2026-96566
7.2 HIGH

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions …

Oct 2, 2026
CVE-2026-95817
7.2 HIGH

The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 …

Oct 2, 2026
CVE-2026-95670
7.2 HIGH

The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and …

Oct 2, 2026
CVE-2026-93756
7.2 HIGH

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message …

Oct 2, 2026
CVE-2026-103426
7.2 HIGH

The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versions up to, and including, 2.31.4 due …

Oct 2, 2026
CVE-2026-102772
7.2 HIGH

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, …

Oct 2, 2026
CVE-2026-100182
7.2 HIGH

The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, …

Oct 2, 2026
CVE-2026-100107
7.2 HIGH

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, …

Oct 2, 2026
CVE-2026-102565
7.2 HIGH

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 …

Oct 2, 2026
CVE-2026-92820
8.1 HIGH

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the …

Oct 2, 2026
CVE-2026-92174
7.5 HIGH

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter …

Oct 2, 2026
CVE-2026-91828
7.5 HIGH

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that …

Oct 2, 2026
CVE-2026-90438
7.2 HIGH

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) …

Oct 2, 2026
CVE-2026-15897
8.8 HIGH

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. …

Oct 2, 2026
CVE-2026-10026
7.2 HIGH

The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient …

Oct 2, 2026
CVE-2026-93367
7.2 HIGH

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 …

Oct 2, 2026
CVE-2026-104123
7.3 HIGH

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation …

Oct 2, 2026
CVE-2026-104120
7.3 HIGH

A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the …

Oct 2, 2026
CVE-2026-103098
7.5 HIGH

Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key …

Oct 2, 2026
CVE-2026-103097
7.5 HIGH

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the …

Oct 2, 2026
CVE-2026-103096
7.5 HIGH

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client …

Oct 2, 2026
CVE-2026-103766
7.2 HIGH

ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. …

Oct 2, 2026
CVE-2026-103761
7.5 HIGH

Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly …

Oct 1, 2026
CVE-2026-86344
7.5 HIGH

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage …

Oct 1, 2026
CVE-2026-51888
7.5 HIGH

langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. …

Oct 1, 2026
CVE-2026-51874
7.5 HIGH

In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace.

Oct 1, 2026
CVE-2026-51873
8.8 HIGH

Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.

Oct 1, 2026
CVE-2026-104051
8.2 HIGH

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint …

Oct 1, 2026
CVE-2026-104020
7.5 HIGH

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, …

Oct 1, 2026
CVE-2026-56661
7.5 HIGH

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update …

Oct 1, 2026
CVE-2026-54049
8.7 HIGH

Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores …

Oct 1, 2026
CVE-2026-53964
7.2 HIGH

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, …

Oct 1, 2026
CVE-2026-103484
8.8 HIGH

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

Oct 1, 2026
CVE-2026-102667
8.3 HIGH

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access …

Oct 1, 2026
CVE-2026-55232
7.6 HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF …

Oct 1, 2026
CVE-2026-55231
7.2 HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed …

Oct 1, 2026
CVE-2026-55230
8.7 HIGH

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML …

Oct 1, 2026
CVE-2026-15911
7.4 HIGH

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

Oct 1, 2026
CVE-2026-104059
8.1 HIGH

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending …

Oct 1, 2026
CVE-2026-104057
7.5 HIGH

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages …

Oct 1, 2026
CVE-2026-97662
8.2 HIGH

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate …

Oct 1, 2026
CVE-2026-68496
7.5 HIGH

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. …

Oct 1, 2026
CVE-2026-68495
7.5 HIGH

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. …

Oct 1, 2026
CVE-2026-104018
8.8 HIGH

An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain …

Oct 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.